Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43670
Total
3528
Critical
13050
High
12909
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-61165 | UNKNOWN | — | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | Aug 26, 2026 |
| CVE-2025-61164 | UNKNOWN | — | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. | Aug 26, 2026 |
| CVE-2025-61163 | UNKNOWN | — | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin … | Aug 26, 2026 |
| CVE-2025-61162 | UNKNOWN | — | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint | Aug 26, 2026 |
| CVE-2026-76784 | UNKNOWN | — | Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge … | Aug 26, 2026 |
| CVE-2026-58474 | HIGH | 8.8 | whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to … | Aug 26, 2026 |
| CVE-2026-54256 | MEDIUM | 5.4 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget … | Aug 26, 2026 |
| CVE-2026-47841 | HIGH | 7.4 | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring … | Aug 26, 2026 |
| CVE-2026-47837 | MEDIUM | 6.8 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This … | Aug 26, 2026 |
| CVE-2026-47836 | HIGH | 7.2 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config … | Aug 26, 2026 |
| CVE-2026-32639 | MEDIUM | 6.8 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor … | Aug 26, 2026 |
| CVE-2026-32593 | MEDIUM | 5.9 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is … | Aug 26, 2026 |
| CVE-2025-56798 | UNKNOWN | — | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication … | Aug 26, 2026 |
| CVE-2025-29419 | UNKNOWN | — | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. | Aug 26, 2026 |
| CVE-2023-42179 | UNKNOWN | — | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | Aug 26, 2026 |
| CVE-2026-80153 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2026-35445 | UNKNOWN | — | Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler … | Aug 26, 2026 |
| CVE-2026-32258 | HIGH | 8.1 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor … | Aug 26, 2026 |
| CVE-2026-32257 | HIGH | 8.1 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings … | Aug 26, 2026 |
| CVE-2020-15878 | UNKNOWN | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a … | Aug 26, 2026 |
| CVE-2020-15876 | UNKNOWN | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a … | Aug 26, 2026 |
| CVE-2020-15874 | UNKNOWN | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the … | Aug 26, 2026 |
| CVE-2026-81036 | HIGH | 8.1 | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success … | Aug 26, 2026 |
| CVE-2026-81035 | HIGH | 8.1 | Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true … | Aug 26, 2026 |
| CVE-2026-81034 | MEDIUM | 6.5 | Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set … | Aug 26, 2026 |